openstackgerrit | Adrian Turjak proposed openstack/keystone-specs master: Add spec for partial auth tokens https://review.openstack.org/553670 | 00:03 |
---|---|---|
*** oikiki has quit IRC | 00:04 | |
*** oikiki has joined #openstack-keystone | 00:07 | |
*** oikiki has quit IRC | 00:07 | |
*** oikiki has joined #openstack-keystone | 00:09 | |
*** odyssey4me has quit IRC | 00:09 | |
*** odyssey4me has joined #openstack-keystone | 00:09 | |
*** oikiki has quit IRC | 00:11 | |
*** r-daneel has joined #openstack-keystone | 01:06 | |
*** zhurong has joined #openstack-keystone | 01:16 | |
*** r-daneel_ has joined #openstack-keystone | 01:32 | |
*** r-daneel has quit IRC | 01:33 | |
*** r-daneel_ is now known as r-daneel | 01:33 | |
*** zhongjun_ has joined #openstack-keystone | 01:35 | |
*** oikiki has joined #openstack-keystone | 02:13 | |
*** wes_dillingham has joined #openstack-keystone | 02:15 | |
*** jdennis has joined #openstack-keystone | 02:25 | |
*** annp has joined #openstack-keystone | 02:27 | |
*** zhurong has quit IRC | 02:36 | |
*** zhurong has joined #openstack-keystone | 02:37 | |
*** germs has joined #openstack-keystone | 03:17 | |
*** germs has quit IRC | 03:17 | |
*** germs has joined #openstack-keystone | 03:17 | |
*** namnh has joined #openstack-keystone | 03:21 | |
*** germs has quit IRC | 03:22 | |
*** rcernin_ has joined #openstack-keystone | 03:23 | |
*** rcernin has quit IRC | 03:25 | |
*** rcernin_ has quit IRC | 03:29 | |
*** rcernin has joined #openstack-keystone | 03:29 | |
*** rcernin has quit IRC | 03:33 | |
*** rcernin has joined #openstack-keystone | 03:49 | |
*** wxy has quit IRC | 03:56 | |
*** wes_dillingham has quit IRC | 04:02 | |
*** oikiki has quit IRC | 04:07 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:14 | |
*** bhagyashri_s is now known as bhagyashris | 04:33 | |
*** bhagyashris is now known as bhagyashri_s | 04:33 | |
*** bhagyashri_s is now known as bhagyashris | 04:33 | |
*** oikiki has joined #openstack-keystone | 04:36 | |
*** itlinux has quit IRC | 04:39 | |
*** oikiki has quit IRC | 04:58 | |
*** Dinesh__Bhor has joined #openstack-keystone | 04:59 | |
*** Dinesh_Bhor has quit IRC | 05:00 | |
*** zhurong has quit IRC | 05:04 | |
openstackgerrit | Merged openstack/keystone master: Updated from global requirements https://review.openstack.org/553960 | 05:08 |
*** germs has joined #openstack-keystone | 05:18 | |
*** germs has quit IRC | 05:23 | |
*** openstackgerrit has quit IRC | 05:49 | |
*** Suramya_ has joined #openstack-keystone | 05:49 | |
*** Suramya has joined #openstack-keystone | 05:50 | |
*** Dinesh__Bhor has quit IRC | 05:59 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:01 | |
*** Dinesh_Bhor has quit IRC | 06:22 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:25 | |
*** rsxruv has joined #openstack-keystone | 06:28 | |
*** Dinesh_Bhor has quit IRC | 06:29 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:31 | |
*** d0ugal has joined #openstack-keystone | 07:00 | |
*** d0ugal has quit IRC | 07:00 | |
*** d0ugal has joined #openstack-keystone | 07:00 | |
*** zhurong has joined #openstack-keystone | 07:01 | |
*** rcernin has quit IRC | 07:07 | |
*** oikiki has joined #openstack-keystone | 07:17 | |
*** germs has joined #openstack-keystone | 07:18 | |
*** germs has quit IRC | 07:18 | |
*** germs has joined #openstack-keystone | 07:18 | |
*** germs has quit IRC | 07:23 | |
*** oikiki has quit IRC | 07:25 | |
*** oikiki has joined #openstack-keystone | 07:28 | |
*** martinus__ has joined #openstack-keystone | 07:34 | |
*** pcaruana has joined #openstack-keystone | 07:39 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:54 | |
*** zhurong has quit IRC | 07:54 | |
*** tesseract has joined #openstack-keystone | 08:17 | |
*** aloga has quit IRC | 08:24 | |
*** Dinesh_Bhor has quit IRC | 08:34 | |
*** jaosorior has joined #openstack-keystone | 08:40 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:40 | |
*** oikiki has quit IRC | 08:56 | |
*** hoonetorg has quit IRC | 09:19 | |
*** hoonetorg has joined #openstack-keystone | 09:32 | |
*** BlackDex has quit IRC | 09:34 | |
*** Dinesh_Bhor has quit IRC | 09:34 | |
*** BlackDex has joined #openstack-keystone | 09:35 | |
*** gus has quit IRC | 09:43 | |
*** jamielennox has quit IRC | 09:43 | |
*** gus has joined #openstack-keystone | 09:44 | |
*** jamielennox has joined #openstack-keystone | 09:48 | |
*** namnh has quit IRC | 10:05 | |
*** mvk has joined #openstack-keystone | 10:13 | |
*** annp has quit IRC | 10:37 | |
*** chason has quit IRC | 10:57 | |
*** chason has joined #openstack-keystone | 10:58 | |
*** edmondsw has joined #openstack-keystone | 11:14 | |
*** edmondsw has quit IRC | 11:18 | |
*** openstackgerrit has joined #openstack-keystone | 11:19 | |
openstackgerrit | Johannes Grassler proposed openstack/keystone-specs master: Add whitelist-extension-for-app-creds https://review.openstack.org/396331 | 11:19 |
*** germs has joined #openstack-keystone | 11:20 | |
*** germs has quit IRC | 11:20 | |
*** germs has joined #openstack-keystone | 11:20 | |
*** germs has quit IRC | 11:25 | |
*** pcichy has joined #openstack-keystone | 11:27 | |
*** chason has quit IRC | 11:35 | |
*** chason has joined #openstack-keystone | 11:35 | |
*** aloga has joined #openstack-keystone | 11:53 | |
*** aloga has quit IRC | 11:54 | |
*** raildo has joined #openstack-keystone | 12:04 | |
*** aloga has joined #openstack-keystone | 12:07 | |
*** wes_dillingham has joined #openstack-keystone | 12:14 | |
*** edmondsw has joined #openstack-keystone | 12:15 | |
*** chason has quit IRC | 12:19 | |
*** chason has joined #openstack-keystone | 12:19 | |
*** gyankum has joined #openstack-keystone | 12:22 | |
*** dmellado has quit IRC | 12:24 | |
*** chason has quit IRC | 12:25 | |
*** chason has joined #openstack-keystone | 12:25 | |
*** dmellado has joined #openstack-keystone | 12:27 | |
*** wxy_ has quit IRC | 12:34 | |
*** wxy_ has joined #openstack-keystone | 12:36 | |
*** panbalag has joined #openstack-keystone | 12:41 | |
*** odyssey4me has quit IRC | 12:42 | |
*** odyssey4me has joined #openstack-keystone | 12:42 | |
*** mvk has quit IRC | 12:44 | |
*** panbalag has left #openstack-keystone | 12:52 | |
openstackgerrit | Johannes Grassler proposed openstack/keystone-specs master: Add whitelist-extension-for-app-creds https://review.openstack.org/396331 | 13:02 |
*** ioni has left #openstack-keystone | 13:14 | |
*** germs has joined #openstack-keystone | 13:21 | |
*** germs has quit IRC | 13:21 | |
*** germs has joined #openstack-keystone | 13:21 | |
*** germs has quit IRC | 13:26 | |
*** jroll has quit IRC | 13:42 | |
*** jroll has joined #openstack-keystone | 13:43 | |
*** mvk has joined #openstack-keystone | 13:54 | |
knikolla | o/ | 13:56 |
lbragstad | o/ | 13:57 |
cmurphy | \o | 13:57 |
knikolla | got approval for Vancouver \o/ | 14:04 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add logging for xmlsec1 installation https://review.openstack.org/553592 | 14:04 |
*** wxy_ has quit IRC | 14:07 | |
*** wxy_ has joined #openstack-keystone | 14:08 | |
lbragstad | knikolla: oh - nice! | 14:09 |
*** felipemonteiro_ has joined #openstack-keystone | 14:12 | |
*** felipemonteiro__ has joined #openstack-keystone | 14:14 | |
*** felipemonteiro_ has quit IRC | 14:18 | |
*** spilla has joined #openstack-keystone | 14:29 | |
*** felipemonteiro__ has quit IRC | 14:34 | |
gagehugo | o/ | 14:35 |
*** gyankum has quit IRC | 14:36 | |
*** felipemonteiro_ has joined #openstack-keystone | 14:42 | |
*** Suramya has quit IRC | 14:48 | |
*** Suramya_ has quit IRC | 14:48 | |
*** itlinux has joined #openstack-keystone | 15:00 | |
*** felipemonteiro_ has quit IRC | 15:04 | |
*** felipemonteiro_ has joined #openstack-keystone | 15:05 | |
*** wes_dillingham has quit IRC | 15:15 | |
*** germs has joined #openstack-keystone | 15:22 | |
*** germs has quit IRC | 15:22 | |
*** germs has joined #openstack-keystone | 15:22 | |
*** germs has quit IRC | 15:26 | |
*** wxy_ has quit IRC | 15:40 | |
*** wxy_ has joined #openstack-keystone | 15:41 | |
*** wes_dillingham has joined #openstack-keystone | 15:46 | |
*** jmlowe_ has quit IRC | 15:46 | |
*** felipemonteiro_ has quit IRC | 15:46 | |
*** josecastroleon has joined #openstack-keystone | 15:47 | |
*** r-daneel has quit IRC | 15:54 | |
*** markvoelker_ has joined #openstack-keystone | 15:56 | |
*** markvoelker has quit IRC | 15:56 | |
*** gyankum has joined #openstack-keystone | 15:59 | |
*** markvoelker has joined #openstack-keystone | 15:59 | |
*** gyankum has quit IRC | 16:00 | |
*** markvoelker_ has quit IRC | 16:01 | |
*** dtruong has joined #openstack-keystone | 16:02 | |
*** pcaruana has quit IRC | 16:07 | |
kmalloc | adriant: you cannot change what an issued token means | 16:21 |
kmalloc | adriant: period. | 16:21 |
*** panbalag has joined #openstack-keystone | 16:21 | |
kmalloc | adriant: so pass back a data structure (do not pass back anything that looks like a token) | 16:22 |
kmalloc | adriant: pass back a structure that can say what the valid auth values are, but it must remain a 401 in this case | 16:22 |
kmalloc | this isn't about being descriptive, you can pass back a json body with a 401. | 16:22 |
kmalloc | but old clients need to work exactly the same in this case, if they don't understand MFA rules. | 16:23 |
kmalloc | you cannot change 401->201 or 202 or anything else. | 16:23 |
kmalloc | that is an API contract break, unless you change the AUTH path completely (see the spec on divorcing auth from versioned API) | 16:23 |
kmalloc | which opens the door to a lot of things. | 16:23 |
kmalloc | but /v3/auth cannot change it's behavior, and partial tokens, 201, etc all is a change in behavior | 16:24 |
kmalloc | adriant: really, don't getme wrong, I want this to be better but I am held to API contracts =/ | 16:24 |
kmalloc | i really want to communicate this, and it does likely mean re-passing the password data (you could offer a one-time hash of a password [with a salt] back that could be re-used without re-supplying the password itself) | 16:25 |
kmalloc | but the tl;dr is "don't change the error code or behavior (especially of the auth path) of an existing API in keystone. | 16:26 |
kmalloc | mordred: ^ cc (since i know you'll want clear auth option info for future plans - and support, it will make things better for zuul and other consumers) | 16:27 |
*** r-daneel has joined #openstack-keystone | 16:27 | |
kmalloc | lbragstad, cmurphy: ^ cc | 16:27 |
kmalloc | i'm holding the -2 on the spec because it is describing an API contract break (Explicitly) | 16:30 |
kmalloc | i want to better inform clients, but we cannot change the API behavior.. we can change the information returned in the 401 -- or we can change the auth path (see other specs) | 16:31 |
*** anyone is now known as meltdown_spectre | 16:42 | |
*** meltdown_spectre is now known as anyone | 16:42 | |
*** anyone is now known as teezod | 16:43 | |
*** teezod is now known as anyone | 16:43 | |
*** gyee has joined #openstack-keystone | 16:49 | |
*** dikonoor has joined #openstack-keystone | 16:51 | |
*** AlexeyAbashkin has quit IRC | 16:51 | |
lbragstad | stepping away to go for a run quick, but i'm going to review the yaml service catalog stuff and then queue up specs | 16:58 |
*** dtruong has quit IRC | 17:05 | |
openstackgerrit | Nicolas Helgeson proposed openstack/keystone master: Extend comparator support for project list by tags https://review.openstack.org/523499 | 17:10 |
cmurphy | kmalloc: adriant what if keystone continues to return a 401 but kept state internaly about the user's auth? then the body of the 401 would say "you're halfway done" and a second auth attempt with the second method could succeed? | 17:16 |
kmalloc | i'd pass back a seeded (time baseD?) hash in the 401 structure that can be validated. | 17:17 |
kmalloc | but just to avoid stateful tracking | 17:17 |
kmalloc | i'm fine with that. the key is it has to remain a 401 unless we're changing the auth path (painful, sadly) | 17:18 |
kmalloc | s/fine with that/fine with what you suggested as well/ | 17:18 |
cmurphy | that sounds good too | 17:18 |
kmalloc | i think we should pass back enough info that the client can act on it. | 17:19 |
kmalloc | whatever that means, but i worry about holding state because it means DB or similar entry that could get... well token table like ick | 17:19 |
kmalloc | ;) | 17:19 |
*** oikiki has joined #openstack-keystone | 17:21 | |
*** d0ugal has quit IRC | 17:21 | |
*** pcichy has quit IRC | 17:31 | |
*** jessegler has joined #openstack-keystone | 17:31 | |
*** techmagus463 has joined #openstack-keystone | 17:34 | |
*** techmagus463 has quit IRC | 17:34 | |
*** oikiki has quit IRC | 17:38 | |
*** panbalag has quit IRC | 17:38 | |
*** jmlowe has joined #openstack-keystone | 17:38 | |
*** Supun has joined #openstack-keystone | 17:40 | |
*** felipemonteiro_ has joined #openstack-keystone | 17:43 | |
*** mvk has quit IRC | 17:44 | |
*** dikonoor has quit IRC | 17:45 | |
*** Supun has quit IRC | 17:46 | |
*** Supun has joined #openstack-keystone | 17:47 | |
*** oikiki has joined #openstack-keystone | 17:49 | |
*** wes_dillingham has quit IRC | 17:49 | |
lbragstad | kmalloc: cmurphy could we only write the state if the user opts into mfa? | 17:52 |
lbragstad | or would we have to write state for every auth? | 17:52 |
kmalloc | i still worry about a large state table | 17:52 |
lbragstad | (making authentication writable again, pre-fernet) | 17:53 |
kmalloc | because arguably lots of folks (and/or domains/sites) will opt into MFA | 17:53 |
lbragstad | sure | 17:53 |
lbragstad | that's fair | 17:53 |
*** oikiki has quit IRC | 17:53 | |
kmalloc | I'd rather do a stateless (HMAC'd?) part of the response that would work for auth | 17:53 |
kmalloc | in a short window | 17:53 |
lbragstad | yeah | 17:54 |
*** oikiki has joined #openstack-keystone | 17:57 | |
*** germs has joined #openstack-keystone | 17:58 | |
*** germs has quit IRC | 17:58 | |
*** germs has joined #openstack-keystone | 17:58 | |
cmurphy | lbragstad: if stateful (but i like stateless better) we'd only need to keep track of users using MFA, otherwise if you got your password wrong you got your password wrong, done deal, no state needs to be recorded | 17:59 |
*** mvk has joined #openstack-keystone | 17:59 | |
kmalloc | ++ | 18:00 |
kmalloc | i mean we could still use Fernet code path [not token, actual just Fernet] for that short-window data. | 18:01 |
lbragstad | sure - that works | 18:03 |
*** germs has quit IRC | 18:03 | |
*** tesseract has quit IRC | 18:07 | |
lbragstad | the yaml catalog stuff feels like it requires a specification | 18:09 |
kmalloc | yes | 18:09 |
lbragstad | i can take a stab at that | 18:09 |
lbragstad | i see we have a blueprint created already and the work to implement it is already associated to the blueprint | 18:10 |
*** wes_dillingham has joined #openstack-keystone | 18:18 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:20 | |
*** AlexeyAbashkin has quit IRC | 18:24 | |
*** dave-mccowan has joined #openstack-keystone | 18:27 | |
*** felipemonteiro__ has joined #openstack-keystone | 18:32 | |
*** wxy_ has quit IRC | 18:33 | |
lbragstad | kmalloc: i might need you to poke some holes in what i'm writing... | 18:34 |
*** wxy_ has joined #openstack-keystone | 18:34 | |
lbragstad | i don't understand a lot of the oddities with the templated backend | 18:34 |
kmalloc | sure | 18:34 |
kmalloc | will look | 18:34 |
lbragstad | that would make yaml a better option. | 18:34 |
lbragstad | i'll post what i have in a few minutes, and just incorporate your comments for "this is better because" or "we should move away from the ``templated`` backend because" | 18:35 |
*** felipemonteiro_ has quit IRC | 18:37 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Specification for yaml-backed catalogs https://review.openstack.org/554320 | 18:46 |
lbragstad | kmalloc: ^ | 18:46 |
lbragstad | wxy_: ^ | 18:46 |
*** openstackgerrit has quit IRC | 18:48 | |
*** pcichy has joined #openstack-keystone | 19:05 | |
*** jmlowe has quit IRC | 19:05 | |
*** jmlowe has joined #openstack-keystone | 19:07 | |
*** knasim-wrs has joined #openstack-keystone | 19:16 | |
knasim-wrs | hey folks, I noticed that Ekystone has a "Parent Region" for each region. I was wondering if we should be setting the Parent Region for our secondary regions (such as in some of our Multi-Region deployments where Keystone is running as a shared service in the Primary region) | 19:18 |
knasim-wrs | I googled a bit and the parent region seems to be used by keystone's OS-ENDPOINT-POLICY API (https://developer.openstack.org/api-ref/identity/v3-ext/#os-endpoint-policy-api | 19:18 |
knasim-wrs | https://developer.openstack.org/api-ref/identity/v3-ext/#os-endpoint-policy-api | 19:18 |
knasim-wrs | I don't know what that does and whether we would want it to see our region deployment with parent/child relationship. | 19:19 |
knasim-wrs | What do you think? | 19:19 |
knasim-wrs | @lbragstad? | 19:19 |
*** pcichy has quit IRC | 19:20 | |
*** AlexeyAbashkin has joined #openstack-keystone | 19:20 | |
*** openstackgerrit has joined #openstack-keystone | 19:24 | |
*** felipemonteiro_ has joined #openstack-keystone | 19:24 | |
openstackgerrit | Nicolas Helgeson proposed openstack/keystone master: Project Tags SQL Refactor https://review.openstack.org/554327 | 19:24 |
*** AlexeyAbashkin has quit IRC | 19:24 | |
*** felipemonteiro_ has quit IRC | 19:25 | |
*** felipemonteiro_ has joined #openstack-keystone | 19:25 | |
*** jmlowe has quit IRC | 19:26 | |
*** felipemonteiro__ has quit IRC | 19:27 | |
*** jmlowe has joined #openstack-keystone | 19:27 | |
adriant | kmalloc: Ok, lets not call it a token, lets call it something else, but yes, lets use the fernet data model. That's ultimately all I need. | 19:29 |
adriant | some way to store the state IN keystone until the next attempt. | 19:29 |
adriant | Make the expiry very short too | 19:29 |
*** jessegler has quit IRC | 19:30 | |
adriant | returned hash password would still be a nope in my book, keystone should "retain the state". The reason I use the token term is because then the method for storing that state matches the token provider (fernet, jwt, uuid). | 19:31 |
adriant | Do we even still have uuid as an option? | 19:31 |
adriant | We can always internally treat it as a partial token to reuse the same models and logic, but never outside of the internals call it a token. | 19:32 |
lbragstad | knasim-wrs: that's a good question | 19:34 |
adriant | I just for the life of me can't think of a different word for it other than token that fits, hence why just making it a new token type felt the most appropriate because ultimately it is very similar logic | 19:35 |
kmalloc | adriant: it should be stateless | 19:36 |
kmalloc | not "Stateful" | 19:36 |
kmalloc | keystone should not maintain the state. | 19:36 |
adriant | kmalloc: but yes, 401 is fine, we can return whatever we want in the header and the body | 19:37 |
kmalloc | adriant: and it will need to be something we can pull out of a 401 body | 19:37 |
lbragstad | knasim-wrs: afaik - the parent_region_id isn't really used anywhere | 19:37 |
kmalloc | or header or whatever | 19:37 |
*** Supun has quit IRC | 19:37 | |
adriant | kmalloc: well not 'stateful' in the rest context, I mean it should act the same way as a token | 19:37 |
lbragstad | knasim-wrs: i can try and dig up the specification to see if there were clear use cases in there | 19:37 |
knasim-wrs | lbragstad: Is it there for legacy reasons? I see a lot of Endpoint Policy stuff has been deprecated / removed in recent releases | 19:37 |
kmalloc | adriant: please do not call it a "token" in this sense. | 19:38 |
kmalloc | so we don't have confusion | 19:38 |
kmalloc | as well. | 19:38 |
adriant | it shouldn't have a password actually in it, just the knowledge that a valid password was once passed. | 19:38 |
adriant | kmalloc: is uuid tokens still a thing? | 19:38 |
kmalloc | the idea behind the "hashed" password would besomething like a re-round hashed hash of the stored password hash | 19:38 |
cmurphy | maybe it's more like a "receipt" than a token? | 19:38 |
kmalloc | so we could compare | 19:38 |
kmalloc | adriant: assume uuid tokens are deprecated and gone | 19:38 |
adriant | ty | 19:38 |
lbragstad | knasim-wrs: original specification - http://specs.openstack.org/openstack/keystone-specs/specs/keystone/juno/endpoint-policy.html | 19:38 |
adriant | k then just use the fernet model for this | 19:38 |
adriant | well, logic not model | 19:39 |
kmalloc | adriant: so, when i said hash, i was thinking something like: password-hash (scrypt or so) the stored hash, and include a timestamp | 19:39 |
adriant | but it won't always be password | 19:39 |
kmalloc | so we could use that as a secret that keystone can verify | 19:39 |
adriant | what if I auth with totp first or some other method? | 19:39 |
lbragstad | i think we'll need a separate key repository for MFA then | 19:39 |
kmalloc | then you're doing it wrong :P | 19:39 |
cmurphy | why does it need anything to do with a password? why not just a random timestamped string? | 19:39 |
kmalloc | lbragstad: yes, that is a concern | 19:39 |
adriant | it needs to be ANY method | 19:39 |
kmalloc | adriant: note the ':P' | 19:40 |
adriant | if we assume password then we're doing it wrong | 19:40 |
kmalloc | sarcasm is lost in irc often | 19:40 |
adriant | kmalloc: it is :( | 19:40 |
adriant | but that's my reason for wanting a receipt | 19:40 |
kmalloc | cmurphy: as long as it's something we can validate as "ours" as stateless, i don't care what goes in it | 19:40 |
adriant | cmurphy: I'm ok with receipt | 19:41 |
lbragstad | there's always a video call to hash out things like this - sarcasm included ;) | 19:41 |
adriant | we could, but then real yelling is always an option :P | 19:41 |
lbragstad | knasim-wrs: it looks like henry and ayoung implemented it - i can try and follow up with them about the parent region id bits | 19:41 |
knasim-wrs | thanks | 19:42 |
adriant | kmalloc: so 401 is ok, and a not-token receipt that sort of acts like a token works? | 19:42 |
adriant | will that work for you and still solve what I need? | 19:42 |
kmalloc | a non-token receipt that can be acted on is fine. | 19:42 |
adriant | k | 19:42 |
adriant | kmalloc: that's the middle ground I need to make this work :) | 19:42 |
adriant | I'll update the spec, and I'll try and make it to the meeting this tuesday (wednesday for me) | 19:43 |
adriant | I'd like to get the spec into a state we're ready to review by then | 19:43 |
* adriant should get out of bed and actually head to the office... | 19:44 | |
openstackgerrit | Nicolas Helgeson proposed openstack/keystone master: Extend comparator support for project list by tags https://review.openstack.org/523499 | 19:45 |
*** openstackgerrit has quit IRC | 19:48 | |
*** felipemonteiro__ has joined #openstack-keystone | 19:48 | |
*** openstackgerrit has joined #openstack-keystone | 19:51 | |
openstackgerrit | Nicolas Helgeson proposed openstack/keystone master: Project Tags SQL Refactor https://review.openstack.org/554327 | 19:51 |
*** felipemonteiro_ has quit IRC | 19:52 | |
*** felipemonteiro__ has quit IRC | 19:59 | |
*** germs has joined #openstack-keystone | 20:00 | |
*** wes_dillingham has quit IRC | 20:00 | |
*** felipemonteiro_ has joined #openstack-keystone | 20:00 | |
*** felipemonteiro_ has quit IRC | 20:00 | |
*** felipemonteiro_ has joined #openstack-keystone | 20:01 | |
*** germs has quit IRC | 20:04 | |
*** felipemonteiro__ has joined #openstack-keystone | 20:06 | |
*** felipemonteiro_ has quit IRC | 20:09 | |
openstackgerrit | Nicolas Helgeson proposed openstack/keystone master: Project Tags SQL Refactor https://review.openstack.org/554327 | 20:10 |
openstackgerrit | Nicolas Helgeson proposed openstack/keystone master: [WIP] Extend comparator support for project list by tags https://review.openstack.org/523499 | 20:18 |
*** AlexeyAbashkin has joined #openstack-keystone | 20:21 | |
*** AlexeyAbashkin has quit IRC | 20:26 | |
*** jmlowe has quit IRC | 20:51 | |
*** dtruong has joined #openstack-keystone | 20:59 | |
lbragstad | kmalloc: qq on one of your comments here - https://review.openstack.org/#/c/554320/1 | 21:03 |
lbragstad | when you say "Changing the format of the ini breaks current deploys using it." what exactly do you mean? | 21:03 |
kmalloc | if you change the ini input | 21:04 |
kmalloc | it breaks folks | 21:04 |
kmalloc | also the template is an on-disk file | 21:04 |
lbragstad | oh - like changing the key/value part? | 21:04 |
kmalloc | yeah | 21:04 |
lbragstad | is the same true if you rename a service using the sql backend? | 21:04 |
*** itlinux has quit IRC | 21:06 | |
lbragstad | i completely understand the whole usability of modeling complex catalogs with ini-style configs | 21:07 |
kmalloc | no because the service is all relational in sql. | 21:09 |
kmalloc | well it's mostly relational | 21:09 |
*** wes_dillingham has joined #openstack-keystone | 21:10 | |
lbragstad | ahh | 21:10 |
lbragstad | i see | 21:10 |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Specification for yaml-backed catalogs https://review.openstack.org/554320 | 21:12 |
*** jessegler has joined #openstack-keystone | 21:27 | |
*** raildo has quit IRC | 21:30 | |
*** felipemonteiro__ has quit IRC | 21:32 | |
*** jmlowe has joined #openstack-keystone | 21:34 | |
*** gyee has quit IRC | 21:50 | |
*** spilla has quit IRC | 21:56 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Specification for yaml-backed catalogs https://review.openstack.org/554320 | 21:59 |
*** martinus__ has quit IRC | 21:59 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Specification for yaml-backed catalogs https://review.openstack.org/554320 | 22:00 |
*** germs has joined #openstack-keystone | 22:00 | |
*** germs has quit IRC | 22:00 | |
*** germs has joined #openstack-keystone | 22:00 | |
*** germs has quit IRC | 22:05 | |
*** AlexeyAbashkin has joined #openstack-keystone | 22:20 | |
*** AlexeyAbashkin has quit IRC | 22:25 | |
*** rcernin has joined #openstack-keystone | 22:34 | |
*** edmondsw has quit IRC | 22:49 | |
*** oikiki has quit IRC | 23:01 | |
*** david-lyle has joined #openstack-keystone | 23:01 | |
*** AlexeyAbashkin has joined #openstack-keystone | 23:20 | |
*** AlexeyAbashkin has quit IRC | 23:24 | |
*** masber has joined #openstack-keystone | 23:27 | |
*** r-daneel has quit IRC | 23:49 | |
*** jessegler has quit IRC | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!